Cyber Risk Analyst in Stirling

Cyber Risk Analyst in Stirling

Stirling Full-Time 60000 - 80000 ÂŁ / year (est.) No home office possible
M&G plc

At a Glance

  • Tasks: Support cyber security oversight and assess first-line controls to enhance security measures.
  • Company: Join a leading savings and investments firm with over 175 years of innovation.
  • Benefits: Enjoy 38 days annual leave, competitive pension scheme, and comprehensive health cover.
  • Why this job: Make a real impact in cyber security while working in a diverse and inclusive environment.
  • Qualifications: 7+ years in cyber security, strong analytical skills, and relevant certifications required.
  • Other info: Flexible working arrangements and support for personal commitments are available.

The predicted salary is between 60000 - 80000 ÂŁ per year.

Our purpose is to give everyone real confidence to put their money to work. With a heritage dating back more than 175 years, we have a long history of innovation in savings and investments, combining asset management and insurance expertise to offer a wide range of solutions. Our two distinct operating segments, Asset Management and Life, work together to provide access to balanced, long‑term investment and savings solutions.

The Cyber Risk Analyst reports to the Lead Cyber Risk Consultant and is part of the Technology Risk Team, which forms part of the Second Line of Defence in the Non‑Financial Risk function. The Cyber Risk Analyst will support the Lead Cyber Risk Consultant in providing independent second‑line oversight of first‑line cyber security across M&G plc. You will be a subject matter expert who:

  • Evaluates, challenges and supports first‑line with controls across areas such as Threat Intelligence, Vulnerability Management, Security Engineering, Application & Cloud Security, SOC and Security Awareness.
  • Plans Red Team testing and manages stakeholder engagement and remediation follow up.
  • Plans and can perform (where appropriate) scheduled and ad hoc cyber assurance testing to validate remediation and investigate concerns.
  • Provides specialist cyber and technology risk advice to the Non‑Financial Risk team.

This role sits within Risk & Compliance and focuses on delivering clear, independent insight to support informed decision‑making.

Key Responsibilities

  • Provide second‑line oversight of first‑line cyber controls, assessing their design, implementation and effectiveness.
  • Identify and report cyber risks, supporting formal risk processes (RCSAs, assurance actions) to ensure timely closure.
  • Plan and manage second‑line red team programmes and where required support regulatory or auditor testing (e.g., CBEST/FCA/PRA) to drive resilience improvements.
  • Plan and deliver second‑line scheduled and ad‑hoc assurance testing (penetration, red team, vulnerability sampling) to validate first‑line remediation and control effectiveness.
  • Challenge first‑line to track and drive remediation of findings from testing, reviews and incidents, ensuring clear remediation plans and closure.
  • Analyse first‑line cyber processes and technical incident responses to identify gaps, root causes and pragmatic remedial actions.
  • Oversee cyber risk mitigation projects and control improvement initiatives to reduce exposure and strengthen defences.
  • Communicate risk findings and recommendations clearly to stakeholders, enabling timely, informed decision‑making.

Key Knowledge, Skills & Experience

  • 7+ years' experience in financial services, consulting or technology roles in cyber security or technology risk (essential)
  • Broad cyber security expertise: risk management, security architecture, engineering, threat intelligence, vulnerability management and incident response (essential)
  • Understanding of second‑line assurance: risk taxonomy, appetite, KRIs and controls (essential)
  • Experience with red teaming, penetration testing or vulnerability scanning (essential)
  • Knowledge of enterprise security products and cloud (primarily Microsoft Azure) (essential)
  • Familiar with CI/CD, DevSecOps, SAST/security scanning and Agile ways of working
  • Comfortable with risk/issue tracking tools, risk reviews and clear stakeholder reporting
  • Able to produce gap analyses against policies/standards using industry best practice
  • Experience in SOC or incident response teams
  • Excellent report‑writing and communication skills
  • Knowledge of national/international cybersecurity laws, regulations and ethics relevant to financial services
  • Able to work in diverse, multi‑cultural teams with international exposure
  • Curious, analytical and pragmatic problem‑solver

Preferred Education and Professional Qualifications

  • Degree (BSc, MSc or equivalent) in Cyber Security, Computer Science, Engineering or a related discipline.
  • Relevant certifications in cyber security and cloud: CISSP, CISM, CCSP, OSCP, GPEN, GCIH, GCIA, CPSA, CRT, CCT (or equivalent).

What we offer

At M&G, we're committed to helping you thrive and supporting your wellbeing, both at work and beyond. Our benefits are designed to help you balance your professional and personal life, while planning confidently for your future. Our UK benefits include:

  • A valuable pension scheme of 18%, with 13% made up of Employer Contributions and 5% Employee Contributions.
  • Share Save and our Share Incentive Plan, together with access to financial wellbeing and support services.
  • 38 days annual leave including bank holidays, with the opportunity to purchase up to 5 extra days and additional flexibility through our Time Off When You Need It policy.
  • Market leading Inspiring Families policy includes comprehensive support and paid parental leave covering maternity, adoption, surrogacy, and paternity leave.
  • Health & Protection cover including Private Healthcare, Critical Illness cover and Life Assurance for you, with family options.

We have a diverse workforce and an inclusive culture at M&G, underpinned by our policies and our employee‑led networks who provide networking opportunities, advice and support for the diverse communities our colleagues represent. Regardless of gender, ethnicity, age, sexual orientation, nationality, disability or long term condition, we are looking to attract, promote and retain exceptional people. We also welcome those who take part in military service and those returning from career breaks. M&G is also proud to be a Disability Confident Leader, and we welcome applications from candidates with long‑term health conditions, disabilities, or neuro‑divergent conditions. If you need assistance or an alternative means of applying for a role due to a disability or additional need, please let us know by contacting us at: careers@mandg.com

Cyber Risk Analyst in Stirling employer: M&G plc

At M&G, we pride ourselves on being an exceptional employer that fosters a supportive and inclusive work environment. With a strong commitment to employee wellbeing, we offer generous benefits such as an 18% pension scheme, 38 days of annual leave, and comprehensive family support policies. Our culture encourages professional growth and collaboration, making it an ideal place for talented individuals to thrive in the dynamic field of cyber risk management.
M&G plc

Contact Detail:

M&G plc Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Cyber Risk Analyst in Stirling

✨Tip Number 1

Network like a pro! Reach out to folks in the industry, attend meetups, and connect on LinkedIn. You never know who might have the inside scoop on job openings or can put in a good word for you.

✨Tip Number 2

Prepare for interviews by researching the company and its culture. Understand their approach to cyber risk and think about how your skills can add value. Tailor your responses to show you're the perfect fit!

✨Tip Number 3

Practice makes perfect! Do mock interviews with friends or use online platforms. Get comfortable talking about your experience in cyber security and be ready to discuss real-world scenarios.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we love seeing candidates who are proactive about their job search.

We think you need these skills to ace Cyber Risk Analyst in Stirling

Cyber Security Expertise
Risk Management
Security Architecture
Threat Intelligence
Vulnerability Management
Incident Response
Red Teaming
Penetration Testing
Vulnerability Scanning
Microsoft Azure
CI/CD
DevSecOps
Report Writing
Communication Skills
Analytical Problem-Solving

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Cyber Risk Analyst role. Highlight your relevant experience in cyber security, risk management, and any specific tools or methodologies you've used. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how your background makes you a great fit for our team. Be sure to mention any specific projects or achievements that demonstrate your expertise.

Showcase Your Communication Skills: As a Cyber Risk Analyst, clear communication is key. In your application, make sure to showcase your ability to convey complex information simply and effectively. This could be through examples of reports you've written or presentations you've delivered.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way to ensure your application gets to us quickly and efficiently. Plus, you'll find all the details about the role and our company culture there!

How to prepare for a job interview at M&G plc

✨Know Your Cyber Stuff

Make sure you brush up on your knowledge of cyber security principles, especially around risk management and threat intelligence. Be ready to discuss your experience with red teaming and vulnerability management, as these are key areas for the Cyber Risk Analyst role.

✨Showcase Your Problem-Solving Skills

Prepare examples that highlight your analytical and pragmatic problem-solving abilities. Think about times when you've identified gaps in processes or implemented effective remediation plans, as this will demonstrate your capability to handle the responsibilities of the role.

✨Communicate Clearly

Practice articulating complex cyber risk concepts in a way that's easy to understand. You’ll need to communicate findings and recommendations to stakeholders, so being able to convey your thoughts clearly is crucial. Consider doing mock interviews to refine your communication style.

✨Understand the Company Culture

Familiarise yourself with M&G's values and culture, especially their commitment to integrity and collaboration. Be prepared to discuss how your personal values align with theirs, and think about how you can contribute to creating an exceptional workplace.

Cyber Risk Analyst in Stirling
M&G plc
Location: Stirling

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>